Data Privacy Challenges in the Age of Artificial Intelligence Under India’s Digital Personal Data Protection Act, 2023
Abstract
India’s Digital Personal Data Protection Act, 2023 (DPDP Act) arrived as the country’s first comprehensive privacy statute, filling a regulatory void that ad hoc provisions under the Information Technology Act, 2000 had long struggled to cover. Yet the legislation was conceived primarily as a general data-protection instrument, not as a direct response to the governance challenges posed by artificial intelligence. This paper argues that the Act’s architecture contains four structural gaps when assessed against AI-specific privacy risks: the legal status of machine-generated inferences about individuals remains undefined; there is no statutory right against consequential automated decisions; obligations on Data Fiduciaries regarding algorithmic transparency are thin; and the broad exemptions granted to State instrumentalities sit uncomfortably with the proportionality standard mandated by the Supreme Court’s right-to-privacy ruling.